Sort incident actions by phase
Categorize common incident actions into the correct response phase.
Place each action in the response phase where it primarily belongs. Detection & analysis Containment Eradication Recovery Export EDR timeline and identify related hosts Isolate the affected server from the network Remove the malicious scheduled task and rotate the abused account Restore the service from validated backup with heightened monitoring Determine whether the suspicious login touched production data Block the attacker IP and revoke active sessions Delete persistence artifacts found during host analysis Return the application to users after trust gates are met
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in